Vulnerabilities / Threats
12/5/2017
01:45 PM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
50%
50%

Bitcoin Sites Become Hot Targets for DDoS Attacks

The Bitcoin industry is now one of the top 10 most-targeted industries for DDoS campaigns. Price manipulation could be one goal, Imperva says.

The massive surge in Bitcoin prices in recent months suddenly has made online cryptocurrency exchanges and services popular targets for distributed denial-of-service (DDoS) attacks.

This Monday, Bitfinex, one of the largest US dollar Bitcoin exchanges in the world, said it was the victim of a DDoS attack that knocked it offline for a short period of time. The company reported a similar incident just a few days earlier, and at least one other incident in June affected withdrawals and deposits of the then newly launched IOTA cryptocurrency.

In a report released Tuesday, security vendor Imperva said that nearly three in four of the 27 enterprise Bitcoin sites that are using the company's services were hit with DDoS attacks in the last quarter. From being hardly a blip on the radar of most cybercriminals earlier this year, the Bitcoin industry emerged as one of the top 10 most-targeted industries for denial-of-service campaigns in the third quarter of 2017. 

Online gambling and gaming sites continued to be the most heavily targeted, as usual, and accounted for 34.5% and 14.4% of all DDoS attacks last quarter, respectively. Internet service providers, financial companies, the retail sector, and software vendors also were seriously affected by DDoS attacks, in keeping with previous trends, Imperva's report said. But with 3.6% of all DDoS attacks aimed against it last quarter, the Bitcoin sector suddenly found itself thrust into the list of most-attacked industries for the first time, says Igal Zeifman, director and security evangelist at Imperva.

The attacks are a textbook example of cybercrooks following the money, Zeifman says. With Bitcoin trading at near-record highs, attackers may be attempting to shake down sites dealing with the cryptocurrency by threatening to disrupt services or to take them offline totally via DDoS attacks. It is also conceivable that cybercriminals and their hired guns are trying to manipulate Bitcoin prices through such disruption, Ziefman says.

In recent months, it has taken little to cause big fluctuations in Bitcoin pricing. In September, for instance, Bitcoin prices fell by as much as 24% in a little over a week after JP Morgan chief executive Jamie Dimon called Bitcoin a fraud.

Financially motivated entities have also taken advantage of the unregulated nature of the Bitcoin ecosystem to drive sudden changes in Bitcoin prices by showing intent to buy or sell very large volumes and then canceling the transaction before it is executed. Given the relative ease with which some have manipulated Bitcoin prices, it is possible that cybercriminals are trying to trigger and profit from price fluctuations via outages at big exchanges.

"I believe that the reported sharp increase in DDoS attacks on Bitcoin and cryptocurrency sites during the last quarter is an attempt at manipulation of cryptocurrency prices, rather than an attempt at extortion," says Martin McKeay, global security advocate at Akamai, which released its own DDoS quarterly update last week.

"There is much more money to be made in casting the stability of a cryptocurrency site and affecting a change in cryptocurrency prices than there is to be made in a simple extortion scam," he says. If attackers can predict or control the timing of a surge or a drop in prices, they can make significantly more money than they could get from a single company in a ransom, he says.

Another option is that the attacks could be directed by a competing type of cryptocurrency network or by a competing system, McKeay says. "When users find themselves unable to quickly and reliably access their currency, it is not unusual for them to switch to a more reliable service." Small organizations in other sectors have shown a tendency to fund DDoS attacks on a competitor to slow them down, he says. "We may be seeing a similar tactic playing out with cryptocurrencies."

Ilia Kolochenko, CEO of High-Tech Bridge, says that while a single DDoS attack is unlikely to produce tangible results for cybercriminals, a well-planned one could create damage. For example, if a major proponent or Bitcoin trade platform were suddenly to go offline accompanied with fake news about the government seizing its servers, a large-scale panic could ensue and undermine Bitcoin exchange rates, Kolochenko says.

But such attacks would require rigorous preparation and significant resources for execution. "If a dozen Bitcoin exchanges simultaneously go offline at a time of a major negative announcement concerning Bitcoin or cryptocurrency in general, and sellers [aren't] able to sell their Bitcoins, a huge depreciation [could happen]," Kolochenko says.

Related Content:

 

Jai Vijayan is a seasoned technology reporter with over 20 years of experience in IT trade journalism. He was most recently a Senior Editor at Computerworld, where he covered information security and data privacy issues for the publication. Over the course of his 20-year ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
5 Reasons the Cybersecurity Labor Shortfall Won't End Soon
Steve Morgan, Founder & CEO, Cybersecurity Ventures,  12/11/2017
BlueBorne Attack Highlights Flaws in Linux, IoT Security
Kelly Sheridan, Associate Editor, Dark Reading,  12/14/2017
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
The Year in Security: 2017
A look at the biggest news stories (so far) of 2017 that shaped the cybersecurity landscape -- from Russian hacking, ransomware's coming-out party, and voting machine vulnerabilities to the massive data breach of credit-monitoring firm Equifax.
Flash Poll
The State of Ransomware
The State of Ransomware
Ransomware has become one of the most prevalent new cybersecurity threats faced by today's enterprises. This new report from Dark Reading includes feedback from IT and IT security professionals about their organization's ransomware experiences, defense plans, and malware challenges. Find out what they had to say!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.